Search Results for 'malware'

    No search results were found in Documentation!

Results from the Forum
IanGJ
tagDiv Member

Hi sm21nz
I have absolutely no idea about hiding functions in code and malware etc – my ‘expertise’ doesn’t reach that far. I have a colleague who blinds me with science on that kind of stuff. All I know is that a recent non tagDiv themed site I have been working on has been cloned on 2 occasions….thankfully, there wasn’t much content and no real point in cloning them as they are not going to gain much….so will just carry on using a different domain – that will fool them for about 5 minutes 🙂
Good luck with sorting your sites

sm21nz
tagDiv Member

IanGJ – rare man of reason and tip of my hat to you. You are right on the money around some of the words used on this and other threads. I’ll also reiterate that I don’t have a problem with technical bugs nor do I have a problem with fighting piracy. My problem is that these cowboys hid a function in their code that has the ability to take over my site whenever they want and display whatever they want. That is unacceptable. Why would anyone in their right mind allow such a malware code on their site that’s absolutely ideal for any black hatter to attack? Why does tagDiv have to engage in such stratospherically over-the-top measures when they suspect a license isn’t valid, especially at their very first sniff of a license anomaly?

We mustn’t accept or approve of any xenophobic and such language; on that we agree. A**holes, c**ts and w**kers exist in all languages, nations, shapes and sizes. They may be fulltime s**tbags or part-timers, but the fact that they are d**kheads with disgusting business practises, like our friends at tagDiv, has nothing to do with where they’re from, who they love or which fictional character they idolise.

sm21nz
tagDiv Member

It really isn’t unforeseen. If you put that kind of a high-jack feature into your product and make it malware, it was only a matter of time that it activated either by accident, by a hacker or a disgruntled employee. Hiding a feature that allows you to take over a site like that makes you nothing more than pirates! I am not happy giving ANYONE the ability to lock down my site and change what my visitors see whenever they want. That’s not what I look for in a theme.

Bogdan B.
tagDiv Staff

Hi,

That code is not the default code for the search.php file. We do not recognize that code.
You should follow this guide to clean your WordPress and theme of malware:
https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/
Also, you need to make a backup of any code changes if you have any and delete the theme and theme plugins. Install a fresh copy of the Newspaper theme and theme plugins to ensure no malware code is present in the theme files.

I hope this helps.

tizian-ffm
Participant
#0

https://crucero-magazin.de/screenshot.png

The issue type is: Backdoor:PHP/filemanager.11472
Description: File uploading behavior reminiscent of malware

Is that an issue or orginal tagDiv programming?

tizian-ffm
Participant
#0

The issue type is: Backdoor:PHP/filemanager.11472
Description: File uploading behavior reminiscent of malware

Is that an issue or orginal tagDiv programming?

sm21nz
tagDiv Member

With all due respect, Calin, calling what you did an “inconvenience” is the very best thing you could have possibly done. When you took my site down and made me look an absolute fool, I was probably the angriest I have ever been in my life. Then you call it an “inconvenience”… a mild irritant, no big deal. Okay, not a big deal for you – clearly – but let me tell you it was a big deal for me and I fully appreciate the fact that you couldn’t care less and that’s fine.

I’ve yanked every last shred of your malware off my site and I’m slowly getting back on my feet. Go me, right?

If your very first step is to publicly take over the entire site if you even think that your theme hasn’t been paid in full (which it was, by the way), then you possess a very dangerous mind. That’s the equivalent of launching a nuclear missile on live TV at someone who *maybe* walked across the road against a red light.

If you had put a small banner at the bottom of the site saying there appears to be a problem with this site’s license registration that pops up when an admin logs in, that I would find an “inconvenience” but it wouldn’t result in me tearing my hair out and screaming about it online. Your very first step was to take my site down and publicly call me a thief and that, young Calin, is a step beyond “inconvenience”.

You stepped too far doing that. I really would’ve preferred had you not chosen to do that, Calin.

MarcKHowe
Participant
#0

Because they have been replaced by malware. How do I download direct instead of via the backend.

Bettina
tagDiv Staff

Hello!

I recommend you to check and clean your files: https://askwpgirl.com/10-steps-remove-malware-wordpress-site/
After that, you should reinstall everything, starting with the WordPress, theme, plugins so that it will be a clean install.

Thank you!

Meranda Devan
Participant
#0

I use newspaper on all of my websites. I like this theme so much, and how customizable it is that I have it on several websites.

Last month my websites were hacked, and I got a re-direction notice. It was devastating to me.

It took my husband a whole day to figure out.

Someone was able to enter, and set themselves up as an admin.

After looking through the files on your forum, I see this has happened in the past.

After logging into my websites again, I see multiple new admins.

We have plugins that include:

Sucuri Security – Auditing, Malware Scanner and Hardening
Wordfence Security

I may have to consider moving to another theme.

My theme is up to date, and my wordpress is up to date.

Meranda

Bettina
tagDiv Staff

Hello!

I recommend you to check and clean your files: https://askwpgirl.com/10-steps-remove-malware-wordpress-site/
After that, you should reinstall everything, starting with the WordPress, theme, plugins so that it will be a clean install.

Thank you!

wf84
Participant
#0

When my site loads, a yellow flash appears. This is theme related I am sure, what is it?
look at https://malware.guide

Calin
tagDiv Staff

Hi tomasamayo,
If you get the theme from themeforest, then should be no problems.
Also, what tools do you use those malwares ?
Thank you!

tomasamayo
Participant
MALWARE - topic
#0

I am installing the newspaper theme in several sites that I have, and in several hosting services of my clients and in all of them I have noticed that there are a lot of malware, I do not understand why it pulls a lot of malware if it is a paid theme

LKennedy
tagDiv Member

Also, Here is a list of current plugins:
All-in-One WP Migration
Anti-Malware Security and Brute-Force Firewall
Antispam Bee
Classic Editor
Elfsight Instagram Feed CC
Gravity Forms
Visual Composer Add-on Image Hotspot with Tooltip
Image Hover Effects Ultimate
Image Hover Effects Visual Composer Extension
Saragna – Instagram Social Streams Grid With Carousel
ShortPixel Image Optimizer
Unlimited Addons for WPBakery Page Builder
WPBakery Page Builder
Tasty Recipes
WooCommerce
Yoast SEO

kibiribi
Participant
#0

After NewsPaper Template update up to 10.3.9 AntiVirus plugin identified file functions.php 🙂
Quote: “Virus suspected: The daily antivirus scan of your blog suggests alarm. Manual malware scan”
https://prnt.sc/vyfg23
is it yours ? https://prnt.sc/vyfhut
/wp-content/themes/Newspaper/functions.php
line 323:

AntiVirus Version 1.3.10 screen – https://prnt.sc/vyfkv6

AEGISAlliance
Participant
#0

Hello. Ever since I disabled the AMP plugin because of a constant reloading issue with non-AMP mobile version, the adsene ads in the non-AMP mobile version are showing up in their own separate window on posts that users have to scroll down to gradually reveal the ad in the separate window. The separate window says “advertisement” at the top and “scroll to continue” at the bottom. It’s cutting off a line of text in posts and killing my ad revenue.

Is adsense doing this or is it your mobile theme plugin? I don’t see a malware warning in my Cpanel Immunify 360 settings. I’ve just disabled adsense auto ads and from it modifying my mobile ad codes, could take up to an hour to reflect that on my site.

Please help if possible. Thank you.

Simion C.
tagDiv Staff

Hi,

I have no idea what you are talking about unfortunately. If you are saying that the theme package contains malware, that would be very unusual. We and also Envato always scan the package before it is available on themeforest.

If your website have been infected with malware, that is a different thing. Try some suggestions to get rid of the malware
https://sucuri.net/guides/how-to-clean-hacked-wordpress/
https://www.wpbeginner.com/plugins/how-to-scan-your-wordpress-site-for-potentially-malicious-code/
https://makeawebsitehub.com/scan-wordpress-hidden-malware/

Thank you!

Simion C.
tagDiv Staff

Hi,

We and I believe Envato as well, always scan the theme package available on themeforest. I have scanned however the theme itself, and the file your hosting mentions that contains malware, with virustotal -> https://prnt.sc/ucwt1p From what I can see there are no issues with it.
I believe you are using an older theme version, is that correct? The file you mention is not in the theme folder anymore, it is in the composer plugin. If you are indeed using an older theme, please consider updating https://tagdiv.com/newspaper/ The theme should always be kept up to date if possible.

Also if the website files do indeed contain malware, please try some suggestions from here for example https://www.wpbeginner.com/plugins/how-to-scan-your-wordpress-site-for-potentially-malicious-code/

Thank you!

AFAmagazin
Participant
#0

Hi Support-Team,

my hosting provider send me a mail that it has found a malware in Newspaper (path: wp-content/themes/Newspaper/includes/wp_booster/td_help_pointers.php)

The identified reason is: PHP.EVAL.CRYPT
What can I do about this?

Thanks and best regards!

Calin
tagDiv Staff

Hi,

I just checked this on my install and for me this code is not inserted in plugins.
I think that you have the same problem as in this topic -> https://wordpress.org/support/topic/have-you-cover-this-malware-yet/

Thank you!

Vlad S
tagDiv Staff

Hello !

Please let us know what tool you have used. we tried going on Totalscan.com but this is not a valid website.

Please note that Newspaper Theme is checked for malware by our team and also by Envato theme so the possibility of this having a virus is zero.

Please make sure that you re-download the package from envato and check it one more time.

Thank you !

Calin
tagDiv Staff

Hi meezan,

As I can see you are using the last version, and everything seems fine, we tested this theme version and there is now malware or code to ad popup ads, please provide some more details about this and some screenshots, in this way I will be able to identify the problem on live website and will be more easy to help you.

Thank you for your understanding!

Anonymous
Inactive
#0

Hi team,

Recently we faced issue on our website that was showing pop up ads & unknown redirects to spam websites from our site upon analyzing it has been occurred multiple times and we have tested many things like plugin enable disable test , .htsacces & core files security malware scans & many things but we haven’t found any root cause for it not as per the engineer we need to re-validate the theme core files to be sure that the popup are not being loaded to the website. hereby i am sharing you the theme file can you ask you, dev team, to have a look if we have any malware or port open somewhere by some malware in the theme files?

This is the latest copy of the theme file from our production server I request you to please let us know by checking

https://drive.google.com/file/d/1dlxc6LT2FZ-Sc6AkT38ShAR3sjANn-gT/view?usp=sharing

Revive the Netherlands
tagDiv Member

Hi,
Someone hacked our website. That was why the Loading… was showing above all pages.
Random articles where uploaded also.
The hacker made some changes in the core files.
We changed passwords and deleted all the malware files with Wordfence.
Not it looks fine again. Domain: geloofsinspiratie.nl

Regards Sam

Viewing 25 results - 351 through 375 (of 681 total)